PT-2026-97189 · WordPress · Jsm Show Post Metadata
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JSM Show Post Metadata WordPress plugin versions prior to 4.9.1
Description
Insufficient escaping of a post meta key before it is output into an inline event-handler attribute within an admin-facing meta box allows users with contributor-level access or higher to perform a Cross-Site Scripting (XSS) attack. This enables the injection of arbitrary JavaScript that executes within the session of a higher-privileged user who reviews the affected post.
Recommendations
Update JSM Show Post Metadata WordPress plugin to version 4.9.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jsm Show Post Metadata